AltaySec · ATLAS 2026.07
AML.T0109

AI Supply Chain Rug Pull

C · Explainer (cannot be honestly simulated in-browser) AML.TA0007 · Defense Evasion

Description

Adversaries may publish legitimate AI components or software, gain user adoption, then push an update with a malicious variant, leading to AI Supply Chain Compromise. More scrutiny is often placed on a supply chain dependency when it is first being considered for inclusion in an AI system. Performing a rug pull may allow adversaries to bypass these defenses and be more likely to achieve Initial Access. Adversaries may Publish Poisoned AI Artifacts, then attempt to gain user trust and increase adoption before performing the rug pull (See AI Supply Chain Reputation Inflation).

Honesty-tier rationale

This technique should be measured against a real defense stack; in-browser, only a simple filter-vs-filter illustration is honest.

Source

← Back to the matrix